A consulting engagement risk register ranking five risks by exposure and by mitigation value, since the two rankings are not the same list. Free template.
Five engagement risks, each with a probability, an impact and a mitigation that costs real money. The ranking by exposure and the ranking by what the mitigation is worth are not the same list, and that is the whole point.
Work Intermediate Risk Register Pro engine
After you install, this is the model to open.
What Could Go Wrong on This Engagement?
- In your spreadsheet, click the Sortia icon in the strip of icons down the right-hand edge. No strip? Click the arrow at the bottom-right to open it. You can also use Extensions, then Sortia, then Open Sortia.
- Click Start from a template and put that name in the search box.
- Pick the card with that name and click Load this template. It arrives on a new tab with real numbers already in it.
This one runs on a Pro engine, and every free install includes five full-quality runs on your own numbers, shared across all five Pro engines rather than five for each. After that, Pro is $199/year.
The answer
- Expected exposure
- $76,750 five risks, priced before you spend anything
- The biggest
- $27,000 client data arriving late or incomplete
- After the mitigations
- $35,400 a little over half bought back
- Best single buy
- +$9,000 net: the $6,000 data spec saves $15,000
Five risks on one client engagement, each with the chance it happens, what it costs if it does, and what a specific mitigation would change. Three of the mitigations cut the probability and leave the impact alone, one cuts the impact and leaves the probability alone, and one does both, which is a distinction worth noticing because they are different kinds of action.
A written extract specification makes late data less likely. A second relationship at director level does nothing at all about a sponsor changing and a great deal about what happens next. Click Run: total expected exposure comes back at $76,750, led by the late data at $27,000. The listed mitigations take exposure down to $35,400, so a little over half of it can be bought back.
The net value column is where the decisions actually are, and it does not agree with the exposure ranking. Late data is first on both lists, worth $9,000 net for $6,000 spent. Scope creep is second on exposure and clears $8,000 for only $3,000, the best ratio on the sheet. The fee dispute is last on exposure and still clears $3,300 for $1,200, which makes milestone billing the cheapest useful thing on this page.
And the interim findings review, at $9,000, removes $3,850 of exposure, so it loses $5,150 in expectation. Three things follow from that. First, ranking risks by exposure tells you where the money is and not where to spend it. Second, the cheap mitigations near the bottom of the list get skipped, because a register is read from the top down.
Third, a mitigation that loses money in expectation is not automatically wrong: an interim review protects a client relationship you may well value at more than $5,150, and the register cannot see that, which is what the band column and your own judgment are for. Note also that three of these five come back banded High, because the band scores probability and impact relative to the largest impact on the sheet, and on a register with a narrow impact range almost everything looks High.
That is a property of the banding rather than of the engagement. Second run: change the late-data probability from 0.45 to 0.25, which is what a client with a data team and a named owner looks like, and run again. Total exposure falls to $64,750, scope creep takes over the top of the ranking, and the extract specification flips from clearing $9,000 to losing $3,000, because a mitigation that takes 25 percent down to 20 is not worth $6,000.
Read that as the rule the whole register runs on: a mitigation is priced against a probability, so when the probability moves the answer moves with it, and a register written a year ago is priced against probabilities nobody holds any more. To adapt it, replace the five rows with the risks from your own scoping call, price each mitigation as the actual cost of doing it rather than as a percentage of anything, and clear the three mitigation figures on any risk you have decided simply to carry.
The model
It arrives on a tab called Template: Engagement Risks, carrying these columns:
- Risk
- Probability
- Impact ($ if it happens)
- Mitigated prob
- Mitigated impact ($ if it happens)
- Mitigation cost
Once it is in your sheet
- The model arrives with real numbers in it and runs as it stands, so you can press the button first and understand it second.
- Change the numbers to yours. The sheet marks which cells are inputs and which hold formulas, and most labels carry a note explaining the row.
- Press the run button at the bottom of the panel. It is labeled for the tool you are in, and the result lands on its own tab, with a written reading of it beside the figures.
Never used Google Sheets? Start here goes the whole way, in seven steps, and assumes nothing.
Next question
- Is your busiest person really the problem?Is Anyone Booked on Two Clients at Once?
- What does one conflict of interest cost you?Who Works on Which Client?
- Which client is quietly about to leave?Which Engagements Renew?
- Which date can you defend when the client pushes?Can I Promise That Date to the Client?
- What is this comp package really worth?
- What is the engagement worth once scope grows?Take the Engagement or Pass?
Every model like this one, and the method behind them: Schedule risk analysis.